Inline Protection  ·  High Availability  ·  Zero Vendor Lock-in

Your hardware.
Our protection.

Low cost. Effective results.
Built for ISPs. Stops burst attacks.
CPU spikes  ·  conntrack floods  ·  router lockups — handled inline.

IronDome turns off-the-shelf servers into carrier-grade DDoS protection appliances — no black boxes, no BGP rerouting, no scrubbing center contracts. You assemble the hardware. We protect the network.

SCROLL
🖥
Your Hardware
Standard market servers. No proprietary appliances. No vendor dependency. Buy anywhere, assemble yourself.
🛡
Our Software
IronDome installed on your hardware, protecting your network — 100% under your control. No recurring per-Gbps fees.
🔗
High Availability
Multi-node cluster with automatic failover. Each node added increases capacity and redundancy — with zero manual configuration.
📡
Central Management
All your clients in a single web panel. Remote deployment, real-time monitoring and configuration from one place.

The attack arrives.
The network goes down.

  • Volumetric floods saturate your router before you react Malicious traffic fills the uplink entirely before any firewall rule can act. By the time you notice, customers are already offline.
  • 🌊
    Scrubbing centers add latency, cost and complexity Rerouting traffic via BGP to a scrubbing center introduces unpredictable latency, operational complexity and variable billing.
  • 💀
    Every minute of downtime burns money and reputation SLA violations, customers calling support, trust eroded. Protection must be active before the attack — not after.

IronDome stops the attack before it reaches you.

Deployed inline between the edge and the core — invisible to the network, relentless against attackers. Your topology doesn't change. Your customers don't know it's there. Neither do the attackers.

🚫
No BGP. No rerouting. Inline protection — attacks are dropped before entering your network, with no traffic detour and no added latency.
Legitimate connections stay up. Active customers remain connected throughout the attack. Protection does not impact valid traffic under any circumstances.
Response in milliseconds. Attacks are identified and blocked in real time — no signature updates, no external rules, no human intervention required.
// How It Works

Your hardware. Our software. That's it.

No per-device licensing. No cost per Gbps. You pay for the software once and run it on your own hardware — forever.

01
🖥

You assemble the hardware

Purchase standard market servers following our recommended component list. No proprietary hardware required. No vendor lock-in. Any supplier, any configuration that meets the requirements — the choice is yours.

02
💿

The ISO sets everything up

Boot the IronDome ISO from a USB drive. A guided wizard handles network configuration, connectivity and manager registration automatically. In under 15 minutes, the node is in production — no manual commands required.

03
🛡

Your network is protected

IronDome automatically scales to the available hardware — no manual parameter tuning. Add nodes to the cluster whenever you need more capacity. The system discovers and integrates them on its own.

// Features

Everything an operator needs.

Built for ISPs and data centers. Every feature validated in real production environments.

🛡

Transparent Inline Protection

Deployed between edge and core without changing your existing topology. The network doesn't perceive the appliance — only the result: attacks blocked before causing any impact.

🔗

High-Availability Cluster

Multiple nodes in a cluster with automatic failover and load distribution. Each new node joins automatically — no manual configuration on existing nodes, no downtime during expansion.

📊

Real-Time Web Dashboard

Complete visibility: node status, live traffic metrics, resource utilization, automatic alerts and protection rule editing — without touching the command line.

🎛

Per-Service Control

Define protection rules and limits specific to each service on your network. Multiple clients and services with custom policies coexist without interfering with each other.

🔄

Updates Without Interruption

Protection rules updated in production without restarting the filter. No maintenance windows for configuration changes. Updates applied instantly across all cluster nodes.

🧠

Automatic Hardware Scaling

IronDome detects available hardware and tunes all parameters automatically. From an entry-level server to a high-density machine — no manual capacity configuration ever.

// Central Management

One panel.
All your clients.

The IronDome Manager is the multi-client platform you use to manage all your deployments from a single place. Each client has an isolated environment with independent access and visibility.

Remote deployment, real-time monitoring, automatic alerts and version control — without accessing each server individually.

  • Automatic deployment via client code — no manual SSH
  • Alerts when a node goes offline or the filter stops
  • Each client sees and manages only their own nodes
  • Encrypted communication between manager and field nodes
  • Software updates across all client nodes with a single click
IronDome Manager — Client Dashboard
Overview
Cluster
Rules
Settings

Network Status

PROTECTED
Filter active on all nodes

Attacks Today

127
intercepted and dropped

Cluster Nodes — 3 active

Appliance 01 — Primary PRIMARY ↑ 14d 6h
Appliance 02 — Redundancy SECONDARY ↑ 14d 6h
Appliance 03 — Redundancy SECONDARY ↑ 14d 5h
// Deployment Modes

Alone or Cluster — you decide.

IronDome runs as a single inline appliance or distributed across an LACP bond between your switches and routers. Completely transparent. No topology changes.

1 NODE
Alone Mode
$100
per node / month

A single IronDome appliance sits inline between the internet edge and your protected network. Simple, reliable and effective for smaller networks and ISPs starting with DDoS protection.

  • One appliance between edge and core
  • No changes to existing routing or switching
  • Web UI with full visibility and control
  • Upgrade to Cluster mode at any time
✓ 30-day free trial included
N NODES
Cluster Mode (LACP)
$50
per node / month · minimum 2 nodes

Multiple IronDome nodes distributed across the LACP bond between your switches or routers. Each node handles its share of the traffic. Total capacity scales linearly with each node added.

  • Nodes sit inside the LACP bond — fully transparent
  • Traffic distributed by the switch LACP hash
  • Add nodes to increase capacity with no downtime
  • Automatic failover if a node goes offline
  • Centralized management across all nodes
✓ 30-day free trial included
// Network Topology

How each mode sits in your network.

Alone Mode
🌐 Internet / WAN
🛡 IronDome Node inline · transparent
🏢 Your Network
Single appliance No topology changes
Cluster Mode (LACP)
🌐 Internet / WAN
Switch / Router WAN
⟵ LACP Bond ⟶
🛡 IronDome 1
🛡 IronDome 2
🛡 IronDome N
⟵ LACP Bond ⟶
Switch / Router LAN
🏢 Your Network
Capacity scales per node Auto failover
// Hardware

Choose your capacity.

Standard market servers. No proprietary hardware. The same platform scales from entry-level ISP to carrier-grade operator.

🔧
Suggested & tested hardware — assembled by you.
The configurations below are reference builds validated by our team. You purchase the components, assemble the server and install our ISO. The $100/$50 per node is the software license only — hardware is entirely your own investment. Other compatible servers may also work.
MID-RANGE — 40 GbE
IronDome 40G
40 GbE
Line rate · ~59 Mpps @ 64B
  • ProcessorIntel Core i7-13700 (LGA1700)
  • Memory32 GB DDR4-3200
  • Interface2× 40 GbE QSFP+ (Intel / Mellanox)
  • ModeAlone or Cluster (LACP)
  • UpgradeCPU + NIC swap — same MB as 10G
Alone Mode (1 node) $100 / node
Cluster Mode (LACP) $50 / node
30-day free trial on all plans
Full line rate on real ISP traffic (avg packet size).
Start Free Trial
CARRIER GRADE — 100 GbE
IronDome 100G
100 GbE
~64 Mpps @ 64B · line rate on real traffic
  • Processori9-13900 or Xeon E-2388G
  • Memory32 GB DDR4
  • Interface2× 100 GbE QSFP28 (Intel / Mellanox)
  • ModeAlone or Cluster (LACP)
  • i9 pathSame MB as 10G & 40G
Alone Mode (1 node) $100 / node
Cluster Mode (LACP) $50 / node
30-day free trial on all plans
i9 = same LGA1700 platform · Xeon = ECC + IPMI
Start Free Trial

Hardware listed is validated by our team — other compatible configurations may also work. These are reference builds, not mandatory purchases.

// Deployment

Zero manual configuration.

Automated ISO with a guided wizard. From cold server to active filter in under 15 minutes.

01

Boot the ISO

Flash the IronDome ISO to a USB drive and boot the server. A fullscreen wizard guides the entire initial setup — network interface, connectivity and manager registration.

▶ Detecting interfaces...
▶ Configuring management
▶ Registering client
▶ Secure tunnel: ACTIVE
02

Automated Deployment

The manager receives the new node notification and runs the full deployment automatically — installation, build and configuration. A real-time progress bar shows each stage on the server screen.

■■■■■■□□□□ 62%
installing components...
ETA: ~4 minutes
03

Configure and Activate

Open the web interface, identify WAN and LAN ports visually, and activate the filter. The system detects the hardware and adjusts all parameters automatically — no manual values needed.

Web Panel → Management
● Filter: ACTIVE
● Network: PROTECTED
// About

Built by engineers.
Tired of the problem.

We met in a graduate program at a university in the northeastern United States — three engineers from England, Germany, and the American Midwest, arguing about systems design over bad coffee at 2am.

What brought us together wasn't a project. It was a shared frustration: small ISPs being destroyed by DDoS attacks that nobody was solving at a price that made sense. The big scrubbing solutions cost more per month than some operators earned. For a regional ISP with twenty years of history and a community depending on it — there was simply nothing.

We built IronDome to fix that. Not a company, not a startup — just a solution. One that runs on hardware you can buy anywhere, that doesn't require BGP rerouting or a security team, and that's priced for the operator in rural Ohio as much as the carrier in London or Hamburg.

We've kept our names off it. We think the work should speak for itself.

Read the full story →
🇬🇧
England · Network Infrastructure
Cluster Architecture & Protocols
Carrier-grade network background. Designed the cluster synchronization layer and high-availability failover logic.
🇩🇪
Germany · Systems Programming
Core Engine & Performance
Low-level systems specialist. Responsible for the packet processing engine — the part that makes the right call on every packet in under a millisecond.
🇺🇸
United States · ISP Operations
Management Platform & Deployment
Grew up around ISP infrastructure in the Midwest. Built everything that has to be simple enough to operate without a dedicated security team.
🛡

Your network protected.
On your hardware.

No scrubbing center contracts. No per-Gbps licensing. No black box.
You bring the hardware. IronDome does the rest — starting right now.

contact@irondome.com  ·  irondome.com